Iran-linked hackers expand infrastructure across Europe and Middle East, report says
Researchers said they identified servers and domains associated with several countries in Europe and the Middle East, potentially pointing to a broader targeting profile for an Iranian hacking group.
Researchers have uncovered new infrastructure linked to an Iranian-linked threat actor that suggests it may be expanding its operations into Britain and other parts of Europe.
The group, known as Tortoiseshell, has been active since at least 2018 and has primarily conducted espionage operations targeting defense, aerospace, technology and military organizations, particularly in the Middle East and the United States.
In a report on Wednesday, researchers at cybersecurity firm Group-IB said they identified servers and domains associated with several countries in Europe and the Middle East, potentially pointing to a broader targeting profile for the group.
Source: https://therecord.media/iran-linked-hackers-expand-infrastructure-europe-middle-east
Related breach coverage
- China-linked Fire Ant Hides Inside Trusted Infrastructure2026-08-31
Fire Ant hijacked Cisco routers, stole credentials and altered logs to hide its tracks, using trusted infrastructure to reach high-value networks. Chinese-linked cyber espionage group Fire Ant has spent the past year quietly graduating from hacking individual computers to hacking the infrastructure that connects them. Sygnia’s new report traces how the group expanded from compromising […]
- UK Power Plant Disabled for Four Days by Iran-Linked Hackers, Concurrent with US Water Attacks2026-08-23
Iran-linked hackers shut down a UK power plant for four days in the first confirmed attack of its kind, concurrent with water infrastructure attacks across 12 US states. Iran-linked hackers shut down a British power plant for four days in what The Telegraph describes as the most successful cyberattack of its kind against UK energy […]
- One Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire2026-09-15
Two China-linked groups ran identical Chrome/Windows zero-day exploits against NGOs, before Chrome’s patch shipped, deploying different backdoors each. Two China-linked threat actors used the same Chrome/Windows zero-day against NGOs starting September 1, 2026, Volexity’s new report lays out the whole chain in detail. On September 1, Volexity detected a spear-phishing campaign by UTA0560 targeting several […]
- Anthropic caught Russia-linked spies using Claude in hacking operations2026-09-11
Anthropic detected and disrupted a Russia-linked cyber-espionage group that used its AI tool Claude in a hacking campaign targeting more than 20 government, intelligence, diplomatic and defense organizations.